2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13552 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is ... |
| CVE-2025-13551 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an un... |
| CVE-2025-13550 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown functi... |
| CVE-2025-13549 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNt... |
| CVE-2025-13548 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects un... |
| CVE-2025-13547 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the fi... |
| CVE-2025-13546 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by t... |
| CVE-2025-13545 | HIGH | 7.2 | 0.3% | Nov 23, 2025 | A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3.... |
| CVE-2025-13544 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is... |
| CVE-2025-13197 | — | — | — | Nov 22, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12561 | — | — | — | Nov 22, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12541 | — | — | — | Nov 22, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-13526 | HIGH | 7.5 | 0.3% | Nov 22, 2025 | The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,... |
| CVE-2025-13318 | MEDIUM | 5.3 | 0.3% | Nov 22, 2025 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and... |
| CVE-2025-13136 | MEDIUM | 4.3 | 0.2% | Nov 22, 2025 | The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-13384 | HIGH | 7.5 | 0.3% | Nov 22, 2025 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i... |
| CVE-2025-13317 | MEDIUM | 5.3 | 0.2% | Nov 22, 2025 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ... |
| CVE-2025-12877 | MEDIUM | 5.3 | 0.2% | Nov 22, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized mod... |
| CVE-2025-12752 | MEDIUM | 5.3 | 0.1% | Nov 22, 2025 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u... |
| CVE-2025-11186 | MEDIUM | 6.4 | 0.2% | Nov 22, 2025 | The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-12889 | MEDIUM | 5.4 | 0.1% | Nov 22, 2025 | With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those ... |
| CVE-2025-65947 | HIGH | 8.7 | 0.3% | Nov 21, 2025 | thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resour... |
| CVE-2025-65946 | HIGH | 8.1 | 0.6% | Nov 21, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error... |
| CVE-2025-12888 | HIGH | 7.5 | 0.3% | Nov 21, 2025 | Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler o... |
| CVE-2025-12678 | — | — | — | Nov 21, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now